Search for projects by name or address
Honeypot is an application-specific rollup designed to challenge the security of Cartesi Rollups. It provides a gamified battlefield to incentivize bug hunters to hack the application to obtain the funds locked in the rollup contract.
Honeypot is an application-specific rollup designed to challenge the security of Cartesi Rollups. It provides a gamified battlefield to incentivize bug hunters to hack the application to obtain the funds locked in the rollup contract.
Consequence: projects without a proper proof system fully rely on single entities to safely update the state. A malicious proposer can finalize an invalid state, which can cause loss of funds.
Learn more about the recategorisation here.
The section shows the operating costs that L2s pay to Ethereum.
This section shows how "live" the project's operators are by displaying how frequently they submit transactions of the selected type. It also highlights anomalies - significant deviations from their typical schedule.
Honeypot archived
2025 Jul 8th
Honeypot funds withdrawn, and validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier turned off.
In the event of a sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. failure, users can force transactions to be included in the project’s chain by sending them to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. There is no delay on this operation.
Currently the system permits invalid state rootsA cryptographic hash succinctly representing a state using a Merkle tree.. More details in project overview.
All of the data needed for proof construction is published on Ethereum L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..
Users can exit funds at any time because contracts are not upgradeable.
Only the whitelisted proposers can publish state rootsA cryptographic hash succinctly representing a state using a Merkle tree. on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development., so in the event of failure the withdrawals are frozen.
All executed transactions are submitted to an on chain smart contract. The execution of the rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. is based entirely on the submitted transactions, so anyone monitoring the contract can know the correct state of the rollup chain.
No compression is used.
The genesis state is derived from the Honeypot Cartesi Machine template, which can be found within the Honeypot server Docker image at /var/opt/cartesi/machine-snapshots/0_0. Alternatively, it is possible to recreate it by following the build procedure outlined in the Honeypot GitHub Repository.
Ultimately, Cartesi DApps will use interactive fraud proofs to enforce state correctness. This feature is currently in development and the Honeypot DApp permits invalid state rootsA cryptographic hash succinctly representing a state using a Merkle tree.. Since Honeypot is immutable, this feature will not be added to the DApp.
Funds can be stolen if an invalid state root is submitted to the system by the configured Authority (CRITICAL).
Discovery rerun on the same block number with only config-related changes.
Discovery rerun on the same block number with only config-related changes.
| + | Status: CREATED |
| contract MerkleV2 (eth:0x33436035441927Df1a73FE3AAC5906854632e53d) | |
| +++ description: None | |
| + | Status: CREATED |
| contract CartesiMathV2 (eth:0xB634F716BEd5Dd5A2b9a91C92474C499e50Cb27D) | |
| +++ description: None | |
| + | Status: CREATED |
| contract Bitmask (eth:0xF5B2d8c81cDE4D6238bBf20D3D77DB37df13f735) | |
| +++ description: Implementation of bit mask with dynamic array. | |
Discovery rerun on the same block number with only config-related changes.
Discovery rerun on the same block number with only config-related changes.
| + | Status: CREATED |
| contract Honeypot (0x0974CC873dF893B302f6be7ecf4F9D4b1A15C366) | |
| +++ description: None | |
| + | Status: CREATED |
| contract History (0x385485FcaCD8AdB70C8A5a6B07155C907e78FAd9) | |
| +++ description: None | |
| + | Status: CREATED |
| contract InputBox (0x59b22D57D4f067708AB0c00552767405926dc768) | |
| +++ description: None | |
| + | Status: CREATED |
| contract ERC20Portal (0x9C21AEb2093C32DDbC53eEF24B873BDCd1aDa1DB) | |
| +++ description: None | |
| + | Status: CREATED |
| contract Authority (0x9DB17B9426E6d3d517a969994E7ADDadbCa9C45f) | |
| +++ description: None | |
| + | Status: CREATED |
| contract CartesiDApp (0x0974CC873dF893B302f6be7ecf4F9D4b1A15C366) { | |
| } | |
| + | Status: CREATED |
| contract History (0x385485FcaCD8AdB70C8A5a6B07155C907e78FAd9) { | |
| } | |
| + | Status: CREATED |
| contract InputBox (0x59b22D57D4f067708AB0c00552767405926dc768) { | |
| } | |
| + | Status: CREATED |
| contract ERC20Portal (0x9C21AEb2093C32DDbC53eEF24B873BDCd1aDa1DB) { | |
| } | |
| + | Status: CREATED |
| contract Authority (0x9DB17B9426E6d3d517a969994E7ADDadbCa9C45f) { | |
| } | |
The operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. is the only entity that can propose blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over.. A live and trustworthy operator is vital to the health of the system.
MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.
Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly.
The user initiates the withdrawal by submitting a regular transaction on this chain. When the blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. containing that transaction is settled the funds become available for withdrawal on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. The process of settling a block usually takes several days to complete. Finally the user submits an L1 transaction to claim the funds.
Funds can be frozen if the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production (CRITICAL).

The Authority owner can submit claims to the Honeypot DApp.

CartesiDApp instance for the Honeypot DApp, responsible for holding assets and allowing the DApp to interact with other smart contracts.
All supported tokens in this escrow are included in the value secured calculation.
Contract that receives arbitrary blobsThe data that a rollup publishes to its L1/data availability (DA) layer. They consist of the L2 transactions that are rolled up, along with some metadata. Blobs are introduced as a new transaction type within Ethereum with EIP-4844, and has rollup scaling specifically in mind. Blobs persist on Ethereum’s Beacon Chain ephemerally. as inputs to Cartesi DApps.
Contract that allows anyone to perform transfers of ERC-20 tokens to Cartesi DApps.
Simple consensusAn agreement on the latest and correct state of a blockchain. Unlike L1 blockchains which coordinate participating nodes with consensus rules, rollups rely on L1s for reaching consensus by checking the state of the rollup smart contract deployed thereon. model controlled by a single address, the owner.
Contract that stores claims for Cartesi DApps.